First published: Wed Dec 31 2003(Updated: )
siteminderagent/SmMakeCookie.ccc in Netegrity SiteMinder does not ensure that the TARGET parameter names a valid redirection resource, which allows remote attackers to construct a URL that might trick users into visiting an arbitrary web site referenced by this parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netegrity Policy Server | ||
Netegrity Policy Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1311 has a moderate severity level due to its ability to potentially redirect users to arbitrary web resources.
To fix CVE-2003-1311, ensure that the TARGET parameter is validated to only allow legitimate redirection resources.
CVE-2003-1311 can lead to phishing attacks as it allows attackers to redirect users to malicious websites.
All versions of Netegrity SiteMinder are affected by CVE-2003-1311, as it does not properly validate the TARGET parameter.
Disabling the TARGET parameter is not recommended; instead, implement proper validation to ensure users are not redirected to untrusted sites.